Security

The 103 checks in the “Security” category of a SQL Server audit: what each one verifies, its severity and the versions covered.

Checks in this category
103
Weight in the score
20
Breakdown by severity
3 critical · 39 high · 30 medium · 6 low · 25 info

Checks in this category

  • SEC001

    SA Account Enabled

    Critical

    The SA (System Administrator) account should be disabled to prevent brute force attacks

    Versions : 2012-2025

  • SEC011

    xp_cmdshell Enabled

    Critical

    xp_cmdshell allows OS command execution and should be disabled

    Versions : 2012-2025

  • SEC015

    Blank Password Logins

    Critical

    Detects SQL logins with blank passwords

    Versions : 2012-2025

  • AUD001

    SQL Audit enabled and running

    High

    Checks that at least one server audit exists and is in STARTED state (a defined but stopped audit records nothing).

    Versions : 2012-2025

  • AUD002

    Audit action groups cover security events

    High

    Checks that the enabled server audit specification covers key groups: successful/failed logins, role membership changes, permission and audit changes.

    Versions : 2012-2025

  • AUD004

    Audit destination off system drive

    High

    Checks that the audit files are not written to the system drive nor to the default data volume, where they are exposed to saturation, deletion or tampering. It compares the drive letter only: file access rights are not inspected. An instance with no file audit at all has nothing to report here — AUD001 is the check that detects a missing audit.

    Versions : 2012-2025

  • PERM001

    CONTROL SERVER granted to logins

    High

    Checks that no login holds the CONTROL SERVER permission, which is equivalent to the sysadmin role.

    Versions : 2012-2025

  • PERM004

    High-impact fixed server roles minimal

    High

    Checks that securityadmin, serveradmin, processadmin, setupadmin, diskadmin, dbcreator and bulkadmin have minimal membership.

    Versions : 2012-2025

  • PERM005

    High-impact fixed DB roles minimal

    High

    Counts members of db_securityadmin and db_accessadmin (excluding dbo) across all databases.

    Versions : 2012-2025

  • PERM006

    db_owner not over-assigned

    High

    Detects databases where principals other than dbo are members of db_owner (full control of the database).

    Versions : 2012-2025

  • PERM007

    ALTER on principals minimal

    High

    Counts principals holding ALTER ANY USER / ALTER ANY ROLE / ALTER on roles, which are privilege-escalation vectors.

    Versions : 2012-2025

  • PERM011

    EXECUTE on registry XPs (xp_reg*) to non-dbo

    High

    Checks that no principal other than dbo has EXECUTE on registry extended procedures (xp_regread, xp_regwrite, ...).

    Versions : 2012-2025

  • PERM012

    EXECUTE on xp_cmdshell to non-dbo

    High

    Detects EXECUTE grants on xp_cmdshell to principals other than dbo, exposing OS command execution.

    Versions : 2012-2025

  • PERM019

    dbo SID consistent (DB vs server)

    High

    Detects databases whose owner_sid matches no server login (orphaned or ambiguous dbo mapping).

    Versions : 2012-2025

  • POST002

    No user-defined CLR assemblies

    High

    Detects user-defined CLR assemblies (sys.assemblies is_user_defined), which expand the in-engine attack surface.

    Versions : 2012-2025

  • POST003

    Trusted assemblies tracked

    High

    Checks sys.trusted_assemblies entries, which bypass CLR strict security and must all be inventoried and justified.

    Versions : 2017-2025

  • POST004

    Engine on supported major version

    High

    Checks that the engine major version is still supported by Microsoft (EOL versions no longer receive security fixes).

    Versions : 2012-2025

  • SEC002

    Password Policy

    High

    Counts the active SQL logins — excluding "sa" and the internal accounts — whose CHECK_POLICY is off (complexity and lockout) and those whose CHECK_EXPIRATION is off (renewal). The two options are independent: a missing CHECK_POLICY fails the check, a missing expiration alone raises a warning. The severity rises to critical when a login without CHECK_POLICY is a member of sysadmin.

    Versions : 2012-2025

  • SEC004

    Sysadmin Members

    High

    Counts the members of the sysadmin role: SQL logins, Windows logins and Windows groups. Compliant up to 5 members, warning from 6 to 10, failure beyond. A Windows group counts as a single member, whatever the number of people it contains.

    Versions : 2012-2025

  • SEC012

    Service Accounts

    High

    SQL services should not run under LocalSystem

    Versions : 2012-2025

  • SEC013

    TRUSTWORTHY Databases

    High

    Checks if user databases have the TRUSTWORTHY flag enabled, which allows privilege escalation

    Versions : 2012-2025

  • SEC014

    Cross-DB Ownership Chaining

    High

    Checks if cross-database ownership chaining is enabled at the server level

    Versions : 2012-2025

  • SEC019

    Server-level and logon triggers

    High

    Inventories server-level triggers, including LOGON triggers, and inspects their body for privileged calls. A LOGON trigger runs on every connection under the engine service account.

    Versions : 2012-2025

  • SEC021

    Server credentials and SQL Agent proxies

    High

    Inventories server credentials and SQL Agent proxies and checks who they are granted to. A proxy allows running code on the operating system under the Windows identity of the attached credential.

    Versions : 2012-2025

  • SEC022

    External REST endpoint invocation enabled

    High

    Checks server option 'external rest endpoint enabled' (new in SQL Server 2025, default 0). When ON it enables sp_invoke_external_rest_endpoint, allowing outbound HTTPS from the engine to arbitrary endpoints (data-egress / SSRF surface).

    Versions : 2025

  • SEC023

    External AI runtimes enabled (local ONNX runtime)

    High

    Checks server option 'external AI runtimes enabled' (new in SQL Server 2025, default 0). When ON it allows loading local ONNX models/libraries via the AI Runtime Host. Microsoft warns a malicious ONNX model can exfiltrate data or execute unauthorized code — native code-execution surface.

    Versions : 2025

  • SEC026

    Holders of ALTER ANY SERVER AUDIT / CONTROL SERVER (audit tamper)

    High

    Enumerates every server principal able to create, alter or drop a SQL Server Audit and therefore silently disable audit logging: explicit grants of ALTER ANY SERVER AUDIT or CONTROL SERVER (which implies it), plus sysadmin members (implicit). A non-sysadmin holder is an unexpected SIEM blind spot.

    Versions : 2012-2025

  • SEC027

    Database ownership / dbo mapping and db_owner least privilege (VA1143)

    High

    Flags least-privilege violations at the database level: user databases owned by a login other than sa (the owner login IS dbo, so an application login owning a database runs as dbo), members of the db_owner fixed role across databases, and the TRUSTWORTHY + owner-is-sysadmin combination — the classic db_owner→sysadmin privilege-escalation vector. Complements SEC004 (sysadmin count) without overlapping it.

    Versions : 2012-2025

  • SEC028

    CLR assemblies with UNSAFE / EXTERNAL_ACCESS permission set (CIS 6.2)

    High

    Scans every accessible database for user-defined CLR assemblies whose permission set is UNSAFE_ACCESS or EXTERNAL_ACCESS. UNSAFE assemblies can call native code and subvert the SQL Server / CLR security boundary (host compromise); EXTERNAL_ACCESS reaches files/network/registry. Microsoft system assemblies (is_user_defined=0) are excluded. Also reports the server 'clr enabled' and 'clr strict security' posture.

    Versions : 2012-2025

  • SEC030

    Windows local groups used as SQL logins (CIS 3.10)

    High

    Lists Windows-group logins (sys.server_principals, type G) whose prefix matches the machine name exactly (SERVERPROPERTY MachineName or, on a clustered instance, ComputerNamePhysicalNetBIOS). Local-group membership is managed by the local administrators of the host, outside any DBA control: whoever administers the machine can add themselves to the group and gain the corresponding SQL access. Complements SURF014 (BUILTIN groups, CIS 3.9); domain groups are out of scope.

    Versions : 2012-2025

  • SEC031

    Admin role members (db_owner / db_ddladmin) in msdb (CIS 3.13)

    High

    Lists members of the db_owner and db_ddladmin roles in the msdb system database other than dbo (msdb.sys.database_role_members). msdb hosts SQL Agent jobs, proxies, Database Mail and backup history: both roles allow creating or altering a job that will run as the Agent service account or a proxy — a privilege escalation that permission reviews miss because it lives in a system database.

    Versions : 2012-2025

  • SEC032

    CHECK_EXPIRATION missing on sysadmin SQL logins (CIS 4.2)

    High

    Lists the SQL-authenticated logins (sys.sql_logins) that are members of sysadmin, or that hold CONTROL SERVER, whose CHECK_EXPIRATION option is disabled: their password never expires. SEC002 reports the absence of CHECK_EXPIRATION on the active SQL logins other than "sa" (warning); here, "sa" and the disabled logins are on the contrary included. CIS 4.2 requires it strictly on the accounts that own the instance, because a sysadmin password set at installation stays valid for years and survives every departure. Disabled logins (typically "sa") are reported but only lower the verdict to a warning.

    Versions : 2012-2025

  • SURF001

    Ad Hoc Distributed Queries off

    High

    Checks that 'Ad Hoc Distributed Queries' (OPENROWSET/OPENDATASOURCE) is disabled. When on, it widens the attack surface toward external sources.

    Versions : 2012-2025

  • SURF004

    No auto-start stored procedures

    High

    Lists procedures flagged ExecIsStartup that run automatically with high privilege when the service starts.

    Versions : 2012-2025

  • SURF009

    FILESTREAM off when unused

    High

    Checks that FILESTREAM is disabled when no FILESTREAM data files exist, avoiding unnecessary surface area.

    Versions : 2012-2025

  • SURF014

    BUILTIN\Administrators not a login

    High

    Checks that BUILTIN\Administrators is not a SQL login, otherwise every local administrator gains access to SQL Server.

    Versions : 2012-2025

  • SURF015

    Features affecting security bundle off

    High

    Composite check of high-risk features (xp_cmdshell, OLE Automation, CLR, Ad Hoc Distributed Queries); all should be disabled.

    Versions : 2012-2025

  • SURF016

    CLR strict security enabled

    High

    Checks that 'clr strict security' is enabled (2017+), treating SAFE/EXTERNAL_ACCESS assemblies as UNSAFE and requiring signing.

    Versions : 2017-2025

  • TLS001

    Force Encryption (TDS) enabled

    High

    Checks that TDS protocol Force Encryption is enabled at the instance level so all client connections are encrypted in transit.

    Versions : 2012-2025

  • TLS002

    Connections actually encrypted

    High

    Inspects current TDS sessions (sys.dm_exec_connections) to detect connections still travelling in plaintext over the network.

    Versions : 2012-2025

  • TLS005

    Mirroring/SSB endpoints use AES

    High

    Checks that database mirroring / Availability Group / Service Broker endpoints use AES encryption rather than RC4 or no encryption.

    Versions : 2012-2025

  • TLS013

    TLS protocol posture and TDS 8.0 strict encryption

    High

    Checks that the obsolete TLS 1.0 and TLS 1.1 protocols are disabled at the SChannel level and, on SQL Server 2012 and 2014, that the engine supports TLS 1.2. From SQL Server 2025 on, also checks that TDS 8.0 strict encryption is enabled. The existing encryption checks indicate that connections are encrypted, never with which protocol.

    Versions : 2012-2025

  • AUD003

    Failed-login auditing

    Medium

    Reads the AuditLevel registry value (login auditing to the SQL Server error log) and checks that failed logins are recorded. Passing: 2 (failed logins only, the shipped default and the CIS 5.3 requirement) and 3 (both failed and successful logins). Failing: 0 (no auditing) and 1 (successful logins only), which record no failed login.

    Versions : 2012-2025

  • DATA001

    Sensitive-data classification applied

    Medium

    Checks that sensitivity labels have been applied to columns (sys.sensitivity_classifications), supporting RGPD/PCI data inventory.

    Versions : 2019-2025

  • PERM002

    Direct server permissions (outside roles)

    Medium

    Detects server permissions granted directly to principals rather than through server roles (excluding CONNECT SQL / VIEW ANY DATABASE).

    Versions : 2012-2025

  • PERM009

    User roles nested in fixed roles (server)

    Medium

    Detects user-defined server roles that are members of fixed server roles, which obscures effective privileges.

    Versions : 2012-2025

  • PERM013

    PUBLIC object/column grants

    Medium

    Counts object- or column-level permissions granted to the PUBLIC role, i.e. to every user.

    Versions : 2012-2025

  • PERM014

    PUBLIC server permissions minimized

    Medium

    Checks that the PUBLIC server role keeps only its default permissions: VIEW ANY DATABASE at server level, and CONNECT on the built-in TSQL endpoints. Those CONNECT grants are excluded from the verdict, as they are present on every instance. CONNECT SQL is not granted to PUBLIC: it is granted login by login, when the login is created.

    Versions : 2012-2025

  • PERM016

    User DBs with guest/public object grants

    Medium

    Counts user databases where guest or public hold object-level permissions, widening the attack surface.

    Versions : 2012-2025

  • PERM017

    model accessible by dbo only

    Medium

    Checks that the model database (template for every new database) exposes no grants to principals other than dbo.

    Versions : 2012-2025

  • PERM020

    Databases not owned by the built-in administrator account

    Medium

    Detects the user databases whose owner is a named login — a personal account or a service account, the check does not tell them apart — instead of the built-in administrator account (SID 0x01).

    Versions : 2012-2025

  • PERM021

    EXECUTE on dangerous XPs to non-dbo

    Medium

    Detects EXECUTE grants to non-dbo on OLE Automation procedures (sp_OA*) and file-access XPs (xp_dirtree, xp_fileexist, ...).

    Versions : 2012-2025

  • PERM022

    High-priv PUBLIC grants in system DBs

    Medium

    Detects high-privilege object permissions (EXECUTE/ALTER/CONTROL/DML) granted to PUBLIC in master, msdb and model.

    Versions : 2012-2025

  • PERM023

    User DB roles nested in fixed roles

    Medium

    Detects, across all databases, user-defined database roles that are members of fixed database roles, hiding effective privileges.

    Versions : 2012-2025

  • PERM024

    WITH GRANT OPTION delegation minimal

    Medium

    Detects non-sysadmin logins holding server permissions granted WITH GRANT OPTION, letting them re-delegate privileges.

    Versions : 2012-2025

  • POST005

    Cumulative Update applied

    Medium

    Checks the patch level; an instance still on RTM with no Cumulative Update is potentially missing months or years of security fixes.

    Versions : 2012-2025

  • SEC003

    Orphaned Users

    Medium

    Orphaned users (without associated login) pose a security risk

    Versions : 2012-2025

  • SEC005

    Guest Account Active

    Medium

    The Guest account should not have permissions in user databases

    Versions : 2012-2025

  • SEC008

    Login Failures

    Medium

    Counts the authentication failures (error 18456) of the last 24 hours in the error log, by error number: the count does not depend on the language of the server. Compliant up to 10 failures, warning beyond.

    Versions : 2012-2025

  • SEC020

    Invalid Windows/AD logins

    Medium

    Finds Windows logins and Active Directory groups that no longer resolve in the directory. These deleted accounts keep every server role and permission they were granted.

    Versions : 2012-2025

  • SEC024

    External AI models registered (sys.external_models - data egress)

    Medium

    Inventories registered external AI models per database (sys.external_models). Each model targets an inference endpoint (Azure OpenAI/OpenAI/Ollama/ONNX Runtime) that may receive row data/embeddings — governance visibility and network-egress flagging.

    Versions : 2025

  • SEC025

    Server-scoped database credentials allowed

    Medium

    Checks server option 'allow server scoped db credentials' (new in SQL Server 2025, default 0). When ON, the host managed identity can be used as a database-level credential (e.g. Managed Identity auth for external models), broadening a privileged credential's scope.

    Versions : 2025

  • SEC029

    Windows logins authenticating with NTLM instead of Kerberos (SPN posture)

    Medium

    Point-in-time snapshot of currently connected Windows-authenticated sessions that arrived over the network using NTLM rather than Kerberos, read from sys.dm_exec_connections.auth_scheme (stable enum, never localized). Remote Windows-auth NTLM indicates a missing or misconfigured Service Principal Name (SPN): no mutual authentication, exposure to NTLM relay, and constrained delegation is impossible. Local and shared-memory connections are excluded (forced to NTLM by design).

    Versions : 2012-2025

  • SURF003

    Scan For Startup Procs off

    Medium

    Checks that 'scan for startup procs' is disabled to prevent automatic execution of procedures at startup.

    Versions : 2012-2025

  • SURF007

    Replication XPs off

    Medium

    Checks that replication extended procedures are disabled when no replication is configured.

    Versions : 2012-2025

  • SURF008

    User Options = 0

    Medium

    Checks that 'user options' is 0, otherwise implicit SET options apply to every session and can silently alter application behaviour.

    Versions : 2012-2025

  • SURF010

    External Scripts off when unused

    Medium

    Checks that 'external scripts enabled' (Machine Learning Services R/Python) is off when unused, since it launches external runtimes.

    Versions : 2016-2025

  • SURF011

    PolyBase export off when unused

    Medium

    Checks that 'allow polybase export' is disabled, otherwise data can be written to external data sources.

    Versions : 2016-2025

  • SURF017

    AUTO_CLOSE enabled on a contained database (CIS 2.15)

    Medium

    Lists contained databases (containment other than NONE) that have AUTO_CLOSE enabled (sys.databases). A contained database authenticates its own users, so even a failed login forces the engine to open the database in order to reject it. With AUTO_CLOSE, every attempt costs a full open/close cycle that an attacker can trigger in a loop over the network (denial of service). The control is considered met when there is no contained database; DBSET001 covers AUTO_CLOSE on every database.

    Versions : 2012-2025

  • SURF018

    A login named 'sa' exists (CIS 2.16)

    Medium

    Verifies that no server principal carries the name 'sa', whichever principal it is: the built-in account (sid 0x01) never renamed, or a login re-created under that name after the rename. Distinct from SEC001 (built-in account disabled, CIS 2.13) and SURF006 (built-in account renamed, CIS 2.14). 'sa' is the first name every brute-force and password-spray tool tries. A disabled 'sa' login downgrades the verdict to a warning.

    Versions : 2012-2025

  • TLS004

    Extended Protection enabled

    Medium

    Checks whether Extended Protection for Authentication (channel binding) is enabled to mitigate relay/MITM authentication attacks.

    Versions : 2012-2025

  • TLS011

    Service account least-privilege

    Medium

    Checks that the SQL Server engine does not run under a high-privilege built-in account (LocalSystem, Network Service, etc.).

    Versions : 2012-2025

  • AUD008

    Error log retention (NumErrorLogs)

    Low

    Reads the NumErrorLogs registry value and checks that at least 12 recycled error logs are kept.

    Versions : 2012-2025

  • DATA004

    UNMASK granted narrowly

    Low

    Checks that no UNMASK permission is granted at the whole-database level (SQL 2022 supports column/schema-level UNMASK).

    Versions : 2022-2025

  • PERM003

    Direct database permissions (outside roles)

    Low

    Counts, across all databases, permissions granted directly to users instead of through database roles.

    Versions : 2012-2025

  • PERM015

    GUEST securable permissions

    Low

    Detects securable permissions (other than CONNECT) granted to the guest account in databases.

    Versions : 2012-2025

  • SURF002

    Remote Access off

    Low

    Checks that the legacy 'remote access' option (RPC sp_addserver) is disabled. This deprecated feature is no longer needed.

    Versions : 2012-2025

  • SURF013

    Sample databases removed

    Low

    Detects demo databases (AdventureWorks, WideWorldImporters, Northwind, pubs) that should not exist in production.

    Versions : 2012-2025

  • AUD005

    Audit ON_FAILURE policy

    Info

    Reports the ON_FAILURE policy of server audits. CONTINUE is accepted: the instance keeps running if the audit can no longer write. FAIL_OPERATION or SHUTDOWN are recommended for high-assurance environments. Informational check, no penalty.

    Versions : 2012-2025

  • AUD006

    Audit retention / rollover configured

    Info

    Detects file audits with no bound (max_file_size = 0 and max_rollover_files = 0), which grow without limit.

    Versions : 2012-2025

  • AUD007

    Database-level audit specifications

    Info

    Checks for enabled database audit specifications, which capture data access (SELECT/EXECUTE) not covered by server-level groups.

    Versions : 2012-2025

  • AUD009

    Audit write waits not throttling

    Info

    Examines waits related to the audit/Extended Events pipeline to detect an audit target unable to keep up (event-loss risk).

    Versions : 2012-2025

  • DATA002

    Likely-PII columns unclassified

    Info

    Heuristically (column name match: email, ssn, iban, dob, card, ...) finds likely-PII columns that carry no sensitivity label.

    Versions : 2019-2025

  • DATA003

    Dynamic Data Masking on sensitive columns

    Info

    Inventories columns protected by Dynamic Data Masking (sys.masked_columns).

    Versions : 2016-2025

  • DATA005

    Row-Level Security policies present

    Info

    Inventories enabled row-level security policies (sys.security_policies).

    Versions : 2016-2025

  • DATA008

    Ledger enabled (integrity required)

    Info

    Checks whether the Ledger feature (cryptographic tamper-evidence) is enabled on databases requiring provable integrity.

    Versions : 2022-2025

  • DATA009

    Ledger digest verification

    Info

    Informational reminder: Ledger tamper-evidence is only meaningful when digests are stored off-box immutably and verified regularly.

    Versions : 2022-2025

  • PERM008

    IMPERSONATE grants inventory

    Info

    Inventories IMPERSONATE permissions granted in databases, which let a principal act as another principal.

    Versions : 2012-2025

  • PERM010

    Empty user-defined DB roles

    Info

    Inventories user-defined database roles with no members (cleanup candidates).

    Versions : 2012-2025

  • PERM018

    Application roles inventory

    Info

    Inventories application roles (type 'A'), which carry a password, present in databases.

    Versions : 2012-2025

  • POST001

    CLR strict security (inventory)

    Info

    Reports the state of the "clr strict security" setting (SQL Server 2017 and later), which treats every assembly as UNSAFE unless it is signed. Inventory without a verdict: the verdict on this setting is carried by SURF016, which reads the same value — counting it twice would penalise a single setting twice.

    Versions : 2017-2025

  • POST006

    Defender for SQL / Vulnerability Assessment

    Info

    Defender for SQL and SQL VA are Azure-managed capabilities; they cannot be evaluated from an on-prem T-SQL collector (informational note).

    Versions : 2012-2025

  • SEC006

    Public Role Permissions

    Info

    Inventory of the permissions held by the PUBLIC server role: server-level grants other than CONNECT SQL and VIEW ANY DATABASE, endpoint grants, and the total. Without a verdict: that one is carried by PERM014, so that a single grant is not counted twice.

    Versions : 2012-2025

  • SEC007

    SQL vs Windows Auth

    Info

    Reads the authentication mode of the instance (IsIntegratedSecurityOnly). Compliant in Windows-only mode; mixed mode is reported. The number of SQL logins is shown for information and is not part of any threshold: it is the server mode that decides whether those logins can be used.

    Versions : 2012-2025

  • SEC009

    Database Owners

    Info

    Databases should not be owned by user accounts

    Versions : 2012-2025

  • SEC010

    TDE Encryption

    Info

    Sensitive databases should use Transparent Data Encryption

    Versions : 2012-2025

  • SEC016

    SQL Server Audit Configured

    Info

    Checks if SQL Server Audit is configured to trace security events

    Versions : 2012-2025

  • SEC017

    High-Privilege Server Roles

    Info

    Identifies logins that are members of high-privilege server roles (sysadmin, securityadmin, serveradmin)

    Versions : 2012-2025

  • SEC018

    Linked Servers Using SA

    Info

    Detects linked servers whose mapping uses the SA account or an admin account

    Versions : 2012-2025

  • SURF005

    Hide Instance enabled

    Info

    Checks that the instance is hidden from SQL Browser enumeration (HideInstance=1), reducing its network visibility.

    Versions : 2012-2025

  • SURF006

    sa account renamed

    Info

    Checks that the principal_id=1 account (default 'sa') has been renamed, which hinders name-based brute-force attacks.

    Versions : 2012-2025

  • SURF012

    Unused Service Broker endpoints

    Info

    Lists Service Broker TCP endpoints that expose the network and should be removed if conversational messaging is unused.

    Versions : 2012-2025

  • TLS012

    SQL Browser / dynamic ports posture

    Info

    Evaluates the instance discovery surface: running SQL Browser service and use of dynamic TCP ports.

    Versions : 2012-2025

Other categories

All checks